First published: Tue Jan 12 2010(Updated: )
The 3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to execute arbitrary code via unspecified vectors, related to a "DLL-loading vulnerability."
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/acroread | <0:9.3-1.el4 | 0:9.3-1.el4 |
redhat/acroread | <0:9.3-1.el5 | 0:9.3-1.el5 |
Adobe Acrobat Reader | <=9.2 | |
Adobe Acrobat Reader | =3.0 | |
Adobe Acrobat Reader | =3.1 | |
Adobe Acrobat Reader | =4.0 | |
Adobe Acrobat Reader | =4.0.5 | |
Adobe Acrobat Reader | =4.0.5a | |
Adobe Acrobat Reader | =4.0.5c | |
Adobe Acrobat Reader | =5.0 | |
Adobe Acrobat Reader | =5.0.5 | |
Adobe Acrobat Reader | =5.0.6 | |
Adobe Acrobat Reader | =5.0.10 | |
Adobe Acrobat Reader | =6.0 | |
Adobe Acrobat Reader | =6.0.1 | |
Adobe Acrobat Reader | =6.0.2 | |
Adobe Acrobat Reader | =6.0.3 | |
Adobe Acrobat Reader | =6.0.4 | |
Adobe Acrobat Reader | =6.0.5 | |
Adobe Acrobat Reader | =6.0.6 | |
Adobe Acrobat Reader | =7.0 | |
Adobe Acrobat Reader | =7.0.1 | |
Adobe Acrobat Reader | =7.0.2 | |
Adobe Acrobat Reader | =7.0.3 | |
Adobe Acrobat Reader | =7.0.4 | |
Adobe Acrobat Reader | =7.0.5 | |
Adobe Acrobat Reader | =7.0.6 | |
Adobe Acrobat Reader | =7.0.7 | |
Adobe Acrobat Reader | =7.0.8 | |
Adobe Acrobat Reader | =7.0.9 | |
Adobe Acrobat Reader | =7.1.0 | |
Adobe Acrobat Reader | =7.1.1 | |
Adobe Acrobat Reader | =7.1.2 | |
Adobe Acrobat Reader | =7.1.3 | |
Adobe Acrobat Reader | =7.1.4 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =8.1 | |
Adobe Acrobat Reader | =8.1.1 | |
Adobe Acrobat Reader | =8.1.2 | |
Adobe Acrobat Reader | =8.1.3 | |
Adobe Acrobat Reader | =8.1.4 | |
Adobe Acrobat Reader | =8.1.5 | |
Adobe Acrobat Reader | =8.1.6 | |
Adobe Acrobat Reader | =8.1.7 | |
Adobe Acrobat Reader | =9.0 | |
Adobe Acrobat Reader | =9.1 | |
Adobe Acrobat Reader | =9.1.1 | |
Adobe Acrobat Reader | =9.1.2 | |
Adobe Acrobat Reader | =9.1.3 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=9.2 | |
Adobe Acrobat Reader | =3.0 | |
Adobe Acrobat Reader | =3.01 | |
Adobe Acrobat Reader | =3.02 | |
Adobe Acrobat Reader | =4.0 | |
Adobe Acrobat Reader | =4.0.5 | |
Adobe Acrobat Reader | =4.0.5a | |
Adobe Acrobat Reader | =4.0.5c | |
Adobe Acrobat Reader | =4.5 | |
Adobe Acrobat Reader | =5.0 | |
Adobe Acrobat Reader | =5.0.5 | |
Adobe Acrobat Reader | =5.0.6 | |
Adobe Acrobat Reader | =5.0.7 | |
Adobe Acrobat Reader | =5.0.9 | |
Adobe Acrobat Reader | =5.0.10 | |
Adobe Acrobat Reader | =5.0.11 | |
Adobe Acrobat Reader | =5.1 | |
Adobe Acrobat Reader | =6.0 | |
Adobe Acrobat Reader | =6.0.1 | |
Adobe Acrobat Reader | =6.0.2 | |
Adobe Acrobat Reader | =6.0.3 | |
Adobe Acrobat Reader | =6.0.4 | |
Adobe Acrobat Reader | =6.0.5 | |
Adobe Acrobat Reader | =7.0 | |
Adobe Acrobat Reader | =7.0.1 | |
Adobe Acrobat Reader | =7.0.2 | |
Adobe Acrobat Reader | =7.0.3 | |
Adobe Acrobat Reader | =7.0.4 | |
Adobe Acrobat Reader | =7.0.5 | |
Adobe Acrobat Reader | =7.0.6 | |
Adobe Acrobat Reader | =7.0.7 | |
Adobe Acrobat Reader | =7.0.8 | |
Adobe Acrobat Reader | =7.0.9 | |
Adobe Acrobat Reader | =7.1.0 | |
Adobe Acrobat Reader | =7.1.1 | |
Adobe Acrobat Reader | =7.1.2 | |
Adobe Acrobat Reader | =7.1.3 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =8.1 | |
Adobe Acrobat Reader | =8.1.1 | |
Adobe Acrobat Reader | =8.1.2 | |
Adobe Acrobat Reader | =8.1.4 | |
Adobe Acrobat Reader | =8.1.5 | |
Adobe Acrobat Reader | =8.1.6 | |
Adobe Acrobat Reader | =8.1.7 | |
Adobe Acrobat Reader | =9.0 | |
Adobe Acrobat Reader | =9.1 | |
Adobe Acrobat Reader | =9.1.1 | |
Adobe Acrobat Reader | =9.1.2 | |
Adobe Acrobat Reader | =9.1.3 | |
Unix Unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The CVE-2009-3954 vulnerability is considered critical due to its potential to allow arbitrary code execution.
To mitigate CVE-2009-3954, upgrade Adobe Reader and Acrobat to version 9.3 or later.
CVE-2009-3954 affects Adobe Reader and Acrobat versions 8.x prior to 8.2 and 9.x prior to 9.3 on Windows and Mac OS X.
Yes, CVE-2009-3954 can be exploited remotely through specially crafted PDF files.
Yes, Adobe has released patches for CVE-2009-3954 in versions 8.2 and 9.3.